Junglewise Threat Intelligence

CVE-2026-34377: ZcashFoundation Zebra consensus split via invalid V5 authorization data

CVE-2026-34377 · Severity: high · CVSS 8.1 · Published 2026-03-31

Technologies: ZcashFoundation Zebrad, zebra-consensus (crates.io). Vendors: crates.io.

Executive brief

Zebra is a software implementation of a Zcash node used to participate in the Zcash cryptocurrency network. A flaw in how the software verifies transactions could allow a malicious miner to cause a 'consensus split,' effectively tricking some nodes into following a different version of the blockchain than the rest of the network. While this does not allow for the creation of fake money or invalid transactions, it can lead to service disruptions, network partitioning, and potential double-spend attacks against the isolated nodes.

Technical details

A logic error exists in the 'find_verified_unmined_tx' function within Zebra's transaction.rs component. The software uses the ZIP-244 transaction identifier (txid) as a lookup key in its verification cache; however, for V5 transactions, the txid excludes the Authorization Data Root (signatures and proofs). An attacker acting as a miner can observe a valid V5 transaction in the mempool and then mine a block containing a modified version of that transaction with the same txid but invalid authorization data. Vulnerable Zebra nodes incorrectly assume the transaction is already verified based on the txid match and accept the invalid block, while the rest of the network (including zcashd and patched Zebra nodes) rejects it, resulting in a chain fork. The issue is fixed in zebrad 4.3.0 and zebra-consensus 5.0.1 by ensuring full integrity checks including authorization data.

Affected products

  • ZcashFoundation zebrad < 4.3.0
  • ZcashFoundation zebra-consensus < 5.0.1

Timeline

  • 2026-03-25: patched: Zebra 4.3.0 released on GitHub
  • 2026-03-27: advisory: GitHub Security Advisory published
  • 2026-03-31: disclosed: CVE published to NVD

References

Related threats